QQudo Tools

敏感信息检测与脱敏

在浏览器本地检测文本中的邮箱、电话、银行卡、IP地址、API密钥、JWT、私钥等敏感信息,确认后脱敏处理。

全程本地处理,不会上传
检测结果仅供辅助参考。由于不同国家、行业和数据格式存在差异,本工具可能产生误报或漏报。请在应用脱敏前逐项检查结果,并保留原始内容的安全副本。本工具不提供法律、合规或安全审计保证。

原始文本

字符数: 0词数: 0行数: 0

检测类型

What is Sensitive Data Detector & Masker?

This tool scans your text for sensitive information such as email addresses, phone numbers, bank card numbers, IP addresses, API keys, JWT tokens, private keys and sensitive URL parameters. All detection and masking happens entirely in your browser – no text is ever uploaded to any server.

How to Use

  1. Paste or type your text in the input area, or import a text file.
  2. Select which types of sensitive data to detect.
  3. The tool automatically scans your text and lists all findings.
  4. Review each detection, mark false positives, and select items to mask.
  5. Click Generate Masked Preview to see the result.
  6. Copy or download the masked text and report.

What is Sensitive Information?

Sensitive information includes any data that could identify a person, compromise security, or violate privacy if exposed. This includes personal identifiers (emails, phone numbers, ID numbers), financial data (bank card numbers), technical secrets (API keys, private keys, JWTs), and network information (IP addresses).

Supported Detection Types

The tool detects email addresses, phone numbers (with international format support), bank card numbers (with Luhn validation), IPv4 and IPv6 addresses, PEM private keys, JWT tokens, API keys with known prefixes, sensitive URL parameters, and custom keywords.

Masking vs Deleting

Masking replaces sensitive values with placeholder text while preserving the document structure. For example, an email becomes z***@example.com. Deleting removes the content entirely. Masking is usually preferred because it maintains readability and context.

Why Manual Confirmation?

Automatic detection can produce false positives – for example, a random number sequence might look like a phone number. Manual confirmation ensures only actual sensitive data is masked, preventing accidental data loss or document corruption.

Risk Levels and Confidence

High risk items include private keys, API keys, JWTs and bank card numbers. Medium risk includes emails, phone numbers and IP addresses. Low risk includes custom keywords and uncertain matches. Confidence is calculated based on format completeness, checksum validation, context keywords and pattern specificity.

Common Masking Methods

Email: mask username keeping domain. Phone: keep first 3 and last 4 digits. Bank card: keep last 4 digits. IP: mask host portion. API key: keep prefix and last 4 characters. JWT and private key: replace entire value with a redaction label.

API Keys and JWT Security Notes

This tool detects API keys by known prefixes (sk-, ghp_, AKIA, etc.) and key=value patterns. JWT tokens are identified by their three-part Base64URL structure. The tool can parse JWT headers to show the algorithm but does not verify signatures. Being able to parse a JWT does not mean the signature is valid or the token is secure.

Data & Privacy

All text processing is performed entirely in your browser. No text content, file names, detection results or matched values are sent to any server. No data is stored in localStorage or cookies. Analytics only records tool-level events without any content.

Limitations

Detection relies on pattern matching and may miss obfuscated sensitive data. Phone number formats vary by region and may produce false positives. ID number detection is limited to common formats. Very large files over 1 MB may cause browser slowdowns. This tool does not replace professional security auditing.

Frequently Asked Questions

Is my text uploaded to a server?

No. All detection and masking happens entirely in your browser. Nothing is uploaded.

Can the tool detect all sensitive information?

No tool can guarantee 100% detection. Pattern-based detection may miss obfuscated data or produce false positives. Always review results manually.

Why is manual confirmation required?

Automatic detection can produce false positives. Manual confirmation ensures only actual sensitive data is masked, preventing accidental data loss.

How do I handle false positives?

Click the Mark FP button next to any detection you believe is incorrect. False positives are excluded from the masked output.

Does it support international phone numbers?

Yes. The tool detects phone numbers with country codes for China, US/Canada, UK, Japan, Korea and other international formats.

Which countries' ID numbers are supported?

The first version focuses on common formats. ID number detection rules are stored in a separate configuration file for easy extension.

How are bank card numbers detected?

The tool uses the Luhn algorithm to validate card numbers. Only numbers that pass the Luhn check are marked as high confidence matches.

Can it verify if API keys are valid?

No. The tool only detects the format of API keys. It never makes network requests to verify keys, which would be a security risk.

Can JWTs be fully decoded?

The tool can parse JWT structure and show the algorithm from the header. It does not verify signatures or decode the full payload by default to protect privacy.

Will private keys appear in detection results?

Private keys are detected and marked as high risk, but the key content is never displayed. The entire key block is replaced with [REDACTED PRIVATE KEY].

Can I import code and log files?

Yes. You can import TXT, LOG, CSV, JSON, XML, HTML, MD, YAML, SQL, JS, TS and other plain text files up to 10 MB.

Can I restore the original text after masking?

Yes. The original text is preserved until you explicitly choose to replace it. You can also use the Undo button to revert.

Does the report contain sensitive original text?

No. The exported report only contains masked values, detection metadata and statistics. No complete sensitive values are included.

Can I use this on my phone?

Yes. The tool is fully responsive and works on mobile browsers. Input and results stack vertically on small screens.